Web Hack List

Collected research

InsertScript: Adobe Reader PDF - Client Side Request Injection

Adobe Reader PDF - Client Side Request Injection

Adobe Reader's XFA submit element copies its textEncoding charset straight into the POST request the PDF makes, so a newline injected there adds arbitrary headers such as Referer, Host or Origin, or pipelines an entirely new request. It fires with no user interaction when the PDF loads in the Adobe ActiveX plugin, and a redirect turns it into a GET while keeping the injected header.

Record

Document
Adobe Reader PDF - Client Side Request Injection
Published by
insert-script.blogspot.com
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of insert-script.blogspot.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .